Which GDPR principle is MOST directly violated when a company trains an AI model on customer data collected for a different stated purpose (e.g., data collected for billing is used to train a marketing AI)?
- A.A. Data minimization
- B.B. Purpose limitation
- C.C. Storage limitation
- D.D. Integrity and confidentiality
Why B is correct
GDPR Article 5(1)(b) establishes the purpose limitation principle: personal data must be collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes. Using billing data to train a marketing AI is incompatible with the original purpose. Data minimization limits volume, not reuse. Storage limitation covers retention periods. Integrity and confidentiality covers security.
Know someone studying for AI Security Fundamentals? Send them this one.